Hacker News new | ask | show | jobs
by josephcsible 992 days ago
A designated domain for domain fronting is useless because it would immediately get added to every middlebox's list of blocked domains.
1 comments

... and this is exactly what will happen to cloudflare-ech.com.

I'm really disappointed with how the ECH spec panned out. It's almost like "make sure middleboxes and GFW can block this" was a hard requirement. They should've made the handshake look like a session resumption (i.e. pre-shared key), since those aren't required to send a server name.